An opinion piece by the CEO of Quod Orbis explains how Provision 29 of the 2024 UK Corporate Governance Code raises expectations for boards to demonstrate that material internal controls are working effectively, not just compliant on paper. It argues that annual, point-in-time reporting is insufficient in complex digital environments spanning cloud, legacy infrastructure and third-party suppliers, and advocates for continuous, real-time assurance and shared reporting architecture across risk, audit and compliance teams so boards can report with confidence and improve cyber resilience.
Questions this post answers
What does Provision 29 of the UK Corporate Governance Code require from boards?
It requires boards to demonstrate that their material internal controls are working effectively, not merely that they exist on paper. Under the 2024 UK Corporate Governance Code, boards must provide consistent evidence that is timely, accurate, and reliable across finance, compliance, and reporting, validated with real-time data rather than periodic, point-in-time reviews. Teams tracking governance requirements like Provision 29 can follow related compliance coverage on daily.dev.
Why is annual testing of security controls considered insufficient under Provision 29?
Annual testing only captures a snapshot at one point in time, similar to a car's annual MOT reporting only on problems present that day. Since businesses continuously evolve their cloud platforms, infrastructure, and third-party integrations, controls deemed effective months earlier may no longer be, leaving decisions based on outdated information. daily.dev helps security and compliance engineers keep up with shifting governance and risk practices.